Metrics
Affected Vendors & Products
Thu, 04 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tianti_project:tianti:*:*:*:*:*:*:*:* |
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tianti Project
Tianti Project tianti |
|
| Vendors & Products |
Tianti Project
Tianti Project tianti |
Tue, 02 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | xujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-01T21:02:06.245Z
Updated: 2025-09-02T15:08:37.422Z
Reserved: 2025-09-01T11:38:37.454Z
Link: CVE-2025-9795
Updated: 2025-09-02T13:43:42.530Z
Status : Analyzed
Published: 2025-09-01T21:15:29.607
Modified: 2025-09-04T16:53:20.223
Link: CVE-2025-9795
No data.